Candidate: CVE-2015-1378 PublicDate: 2017-08-07 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1378 https://github.com/grml/grml-debootstrap/issues/59 Description: cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is writable by non-root users. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_grml-debootstrap: upstream_grml-debootstrap: needs-triage lucid_grml-debootstrap: DNE precise_grml-debootstrap: ignored (reached end-of-life) precise/esm_grml-debootstrap: DNE (precise was needed) trusty_grml-debootstrap: ignored (reached end-of-life) trusty/esm_grml-debootstrap: DNE (trusty was needed) utopic_grml-debootstrap: ignored (reached end-of-life) vivid_grml-debootstrap: not-affected (0.68.1) vivid/stable-phone-overlay_grml-debootstrap: DNE vivid/ubuntu-core_grml-debootstrap: DNE wily_grml-debootstrap: not-affected (0.68.1) xenial_grml-debootstrap: not-affected (0.68.1) yakkety_grml-debootstrap: not-affected (0.68.1) zesty_grml-debootstrap: not-affected (0.68.1) artful_grml-debootstrap: not-affected (0.68.1) bionic_grml-debootstrap: not-affected (0.68.1) cosmic_grml-debootstrap: not-affected (0.68.1) disco_grml-debootstrap: not-affected (0.68.1) devel_grml-debootstrap: not-affected (0.68.1)